CVE-2020-12888

Aliases:UBUNTU-CVE-2020-12888DEBIAN-CVE-2020-12888
Modified
Published: 15 May 2020, 17:02
Last modified:04 Aug 2024, 12:11

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5.3 MEDIUM
v3.1 (nvd)
EPSS Score
0.4% LOW
0% probability +0.31%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

15 May 2020, 17:02
Published
Vulnerability first disclosed
04 Aug 2024, 12:11
Last Modified
Vulnerability information updated

Description

The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
  • v2.0MEDIUMScore: 4.7AV:L/AC:M/Au:N/C:N/I:N/A:C

EPSS Trends

Current EPSS score: 0.40% Percentile: 34%

Techniques & Countermeasures

  • CWE-755Improper Handling of Exceptional Conditions

    The product does not handle or incorrectly handles an exceptional condition.

Affected Systems

  • canonicalubuntu_linux

    14.04 | 16.04 | 18.04 | 20.04

  • debianlinux

    < 5.8.7-1 | < 5.8.7-1 | < 5.8.7-1 | < 5.8.7-1

  • ubuntulinux

    all | < 4.4.0-223.256 | < 4.15.0-118.119 | < 5.4.0-48.52

  • ubuntulinux-aws

    < 4.4.0-1103.108 | < 4.4.0-1139.153 | < 4.15.0-1083.87 | < 5.4.0-1025.25

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1025.25~18.04.1

  • ubuntulinux-aws-fips

    < 4.15.0-2027.27 | all | < 5.4.0-1069.73+fips2

  • ubuntulinux-aws-hwe

    < 4.15.0-1083.87~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1096.106~14.04.1 | < 4.15.0-1096.106~16.04.1 | all | < 5.4.0-1026.26

  • ubuntulinux-azure-4.15

    < 4.15.0-1096.106

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1026.26~18.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde-5.15

    < 5.15.0-1114.123~20.04.1

  • ubuntulinux-azure-fips

    < 4.15.0-2009.10 | all | < 5.4.0-1073.76+fips1

  • ubuntulinux-bluefield

    all

  • ubuntulinux-fips

    < 4.4.0-1073.79 | all | < 4.15.0-1041.46

  • ubuntulinux-gcp

    < 4.15.0-1084.95~16.04.1 | all | < 5.4.0-1025.25

  • ubuntulinux-gcp-4.15

    < 4.15.0-1084.95

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1025.25~18.04.1

  • ubuntulinux-gcp-edge

    all

  • ubuntulinux-gcp-fips

    all | < 5.4.0-1067.71~20.04.1

  • ubuntulinux-gke-4.15

    < 4.15.0-1070.73

  • ubuntulinux-hwe

    < 4.15.0-118.119~16.04.1 | all

  • ubuntulinux-hwe-5.4

    < 5.4.0-48.52~18.04.1

  • ubuntulinux-hwe-edge

    all | all

  • ubuntulinux-intel-iot-realtime

    all

  • ubuntulinux-kvm

    < 4.4.0-1104.113 | < 4.15.0-1075.76 | < 5.4.0-1024.24

  • ubuntulinux-lts-xenial

    < 4.4.0-223.256~14.04.1

  • ubuntulinux-oem

    < 4.15.0-1097.107

  • ubuntulinux-oem-5.6

    < 5.6.0-1028.28

  • ubuntulinux-oracle

    < 4.15.0-1054.58~16.04.1 | < 4.15.0-1054.58 | < 5.4.0-1025.25

  • ubuntulinux-oracle-5.0

    all

  • ubuntulinux-oracle-5.3

    all

  • ubuntulinux-oracle-5.4

    < 5.4.0-1025.25~18.04.1

  • ubuntulinux-raspi

    < 5.4.0-1019.21

  • ubuntulinux-raspi-5.4

    < 5.4.0-1019.21~18.04.1

  • ubuntulinux-raspi-realtime

    all

  • ubuntulinux-raspi2

    < 4.15.0-1071.75 | all

  • ubuntulinux-realtime

    all

  • ubuntulinux-riscv

    < 5.4.0-34.38

  • ubuntulinux-snapdragon

    < 4.15.0-1087.95

  • debiandebian_linux

    9.0

  • fedoraprojectfedora

    31 | 32

  • linuxlinux_kernel

    ≤ 5.6.13

  • netappa700s_firmware

    na

  • netappactive_iq_unified_manager

    na

  • netappbootstrap_os

    na

Showing first 50 affected entries in server-rendered view.

References (22)